7 ms·
I reversed a Node.js malware and found the author
- stanley1337 5y agohey im stanley, didn't know that it was that famous !!!
- easrng 5y agoIt's always PirateStealer, probably because it's open source so it's easy for people to pick up and use instead of exerting effort. Also, you can send a DELETE request to a Discord webhook without any auth, defusing the malware.
- Fabricio20 5y agoI'm still glad the DELETE thing works, I've reported a few times these with a complete writeup to Discord and all I got was a ticket being auto-closed after a month and the webhooks+servers still being up. I personally no longer bother reporting, just straight delete the webhook to stop the spread. Makes you wonder what their security/support team is doing with all those tickets.
- d4mi3n 5y agoThey may not have one, or have one that’s so underwater with larger issues that the rest of the org doesn’t know how to route things to them. Hiring for technical security is hard—you need engineering expertise to find good people, and then you need someone with an infosec background to vet them. Finding a combination of both is surprisingly rare and you usually find infosec folks who can define but not implement a security program, or an engineer that can implement a security program with no idea how to run or grow it. I need more peers in this space. If you’re reading this and are a software engineer looking for a transition please do reach out—email is in my profile. There’s a huge demand for security engineers and not nearly enough engineers interested in doing it.
- cinntaile 5y agoHow do you mean? Do you mean infosec people usually don't have degrees?
- d4mi3n 5y agoThat depends entirely on their backgrounds. I myself do not. The status-quo here isn’t too different than anywhere else in the tech sector. Many security engineers transition into infosec from related fields like IT, DevOps, Network Engineering, Product Engineering, or similar. This tends to work out well since security engineers work closely with all of those areas within an organization.
- raverbashing 5y agoDiscord's fraud and malware response is too simplistic to work Somebody using my email for a discord acct without verification? Sure, go ahead (but I got the "verify your account" emails) Then I "forget" the acct password, bam, account locked. Which is fine by me, since I don't use that email with discord, still...
- tisryno 5y agoYes, you can send a DELETE to a Discord Webhook, but these malware projects have clocked on in most situations and now forward Webhooks through their own domains. For the example of PirateStealer, the kid who made it ran a website where you posted your webhook and it spat out an exe that hid your webhook behind the domain, they even sold "premium" copies with additional security but in reality once they put the webhook behind their own domains they were dual-hooking, so the information was actually sent to 2 webhooks instead of just the 1. Most of the services to create this malware now hide it behind a domain rather than directly exposing the Webhook, so shutting it down isn't as easy.
- FastEatSlow 5y agoFinding the author of most common malware isn't hard, skript kiddies really like their credit for reputation.
- teetertater 5y agoThey also found the person using the script with their discord api key
- technion 5y agoIs it really fair to call someone a "skript kiddie" if they wrote the malware themselves that became "the most common malware" ?
- deviation 5y agoYou beat me to this. This malware is better than some of the work my colleagues can do, and they're being paid a lot of money. Even though it has bad intentions, it's still good software. Credit where credit is due, I guess.
- TravHatesMe 5y agoI feel like a script kiddie is someone that ripped off good code from others, maybe made a few adjustments at most, and claimed it as their own in an attempt to look cool
- openknot 5y agoA misquote or an edit in the original comment occurred, as it now appears as: "Finding the author of most common malware isn't hard." This assertion is different (i.e. Finding the author of [the majority of] malware isn't hard..., versus Finding the author of [the most popularly-used] malware isn't hard...).
- FastEatSlow 5y agoI don't call the authors of most original malware skript kiddies, that term is for the people who copy the common malware with at most a few edits or create Frankenstein creations out of multiple common sources.
- MrStonedOne 5y agoOur discord got hit by the same shit, targeted at our game admins. We are the largest open source multiplayer video game on github, so (compromised) discord friends sending admins messages about "games they made" with exes in them was more effective then it should have been until news and announcements went out.
- donkarma 5y agoyour admins are often underage and more liable to fall for these scams :)
- MrStonedOne 5y agoCalling my admins underage won't get you unbanned karma.
- chana_masala 5y agoWhich game? bzflag is the only one that comes to mind, but I am not a gamer.
- rnotaro 5y agoI had Teeworlds [1] in mind but their game is tg Space Station 13 [2]. [1]https://github.com/teeworlds/teeworlds https://github.com/teeworlds/teeworlds [2]https://github.com/tgstation/tgstation https://github.com/tgstation/tgstation
- Moru 5y agoFrom the HN profile: (/tg/Station13, based off of Space Station 13).
- diogenesjunior 5y agodang can you do something about the redirect link?
- petercooper 5y agoI don't know what the redirect was but given the article is behind the Medium paywall, if it was a t.co redirect, it was probably the submitter's way to let everyone skip the paywall.
- diogenesjunior 5y agoit goes from medium.com to itnext.io why not just use the itnext.io link?
- grepfru_it 5y agoI did the same thing to someone who attacked my gf in high school. They got her with subseven which was extremely easy to remove. Rather than just erase it, I took a copy home with me and analyzed it. Running the strings command uncovered the subseven signatures.. Turns out there was tooling that allowed you to modify the binary and redistribute it. Except the binary had an ICQ address to alert him to my gf’s online presence. He also had his AIM screen name, full name and city in his profile. So I socially engineered him by posing as a classmate. I told him I was going to come by to get the homework for English. He wasn’t sure but I somehow convinced him and got his address. I don’t know why they always talk to strangers, but just like the article the dude responded. I got my friend and we went to pay him a visit. Rang his doorbell, “hi is this l33th4x0r?”. He nodded but had no clue who I was. I mentioned my gf’s screen name and you could see the color leave his face. He stuttered and stammered about how he was just playing and didn’t mean to cause any problems. I said some stern words then left him wondering wtf I was and what just happened. Kinda wish I saved the details (screen name, address, etc) just because of how epic it was at the time
- vmception 5y agoI used to just DDOS people’s AIM and messengers if they crossed me, as a phantom curse attached to them and they had no idea the cause. I would chat with them as normal at the same time, chuckling to myself as they kept falling offline following a barrage of emoticons and requests from my army of chat bots that made their process run out of memory. Eventually I’d bore of it. Or have one of the chatbots tell them not to cross someone again. In your scenario I probably would have said it was the person he got the exploit from, instead of making a link to someone I care about.
- suzzer99 5y agoWay way back in the day, my friend wrote a program that would format the user's Commodore 5 1/4" floppy disk (usually the one that also ran their BBS) if they just tried to load it. They didn't even have to run it. If someone screwed us, we'd create a new identity and upload a file named after a hot new pirated game to their BBS. Then sit back and watch the BBS go offline for a while.
- woodruffw 5y agoThe closed issues on the program in question are very endearing[1]. Skiddie culture has survived all these years! [1]: https://github.com/Stanley-GF/PirateStealer/issues?q=is%3Aissue+is%3Aclosed https://github.com/Stanley-GF/PirateStealer/issues?q=is%3Ais...
- Handytinge 5y agoOpen one complaining about the project being "stolen"[1], goodness! It really hasn't changed. https://github.com/Stanley-GF/PirateStealer/issues/53 https://github.com/Stanley-GF/PirateStealer/issues/53
- caaqil 5y ago> but at some point, I saw NodeRuntime. We can now say it is a NodeJS bundled executable! This is cute, but it's important to lose this naïveté/innocence if you want to analyze more sophisticated malware in the future.
- izanagi1995 5y agoHey, I was not expecting a French speaker here :D Merci de ton commentaire ;) I'm just a beginner in malware analysis and I tried my best to give a starting point to people like me :)
- hankman86 5y agoWhy did you redact the identity of the scammer? Please name and shame them! These people need to be called out and it seems like you’ve got irrefutable proof.
- lolinder 5y agoThese posts show up on every thread like this and it always strikes me as off. It's not that I think the scammer here deserves protection, but the impulse to "name and shame" makes me very uncomfortable. I worry that supporting that impulse, even in cases like this, normalizes the use of internet lynch mobs to exact "justice" (for any subjective value of "justice" that can get enough steam).
- GreenWatermelon 5y agoAlso, remember the reddit and Boston bomber situation? publicly doxxing someone is almost NEVER a good idea.
- Moru 5y agoAlso it would be soo easy to frame someone. That is why we have the legal system we have in most countries. We want to be REALLY sure we get the right person before we do something about it.
- oh_sigh 5y agoWhy are you so credulous to believe any random account on the internet? Not saying the author is a liar. But it sounds like you want to go on a crusade for them after just finding out they exist.
- smorgusofborg 5y ago> it seems like you’ve got irrefutable proof. Or is that irrefutable proof of who was one of their victims?
- hacsky 5y agoOff note: Is there any service where i can submit an executable (.exe) and it tells me if it contains malware?
- reubenbond 5y agotry virustotal.com
- gostsamo 5y agoYep: https://www.virustotal.com/ https://www.virustotal.com/
- praash 5y agoNote that this post's malware is advertised with "Low Detections (0/64)".
- technion 5y agoI'm sure that was true for about ten minutes after it was written, but it's unlikely still the case. This issue appears to suggest detections: https://github.com/Stanley-GF/PirateStealer/issues/45 https://github.com/Stanley-GF/PirateStealer/issues/45 I think I've found a relevant virustotal: https://www.virustotal.com/gui/file/de7535f8c64d7a6ac8094146a02626ca6d2a008ead42a884dfeb1b56047ef5dd/details https://www.virustotal.com/gui/file/de7535f8c64d7a6ac8094146...
- spyder 5y agoAnother one besides virustotal.com is: https://www.hybrid-analysis.com/ https://www.hybrid-analysis.com/
- Nextgrid 5y agoMalware detection relies on signatures and/or heuristics. Signatures won't work with a brand new malware that hasn't been seen before. Heuristics can also be defeated. Antimalware is great for the low hanging fruit but don't expect it to detect something where the author has put effort into it.
- m1117 5y agoLol welcome to the web3.0
- b_u_n_n_y 5y agoExcuse my ignorance, but what does this particular malware do? Control computer? See what the were typing?
- Mashimo 5y ago* Discord Credit Card Stealing * Discord Login Stealing
- smorgusofborg 5y agoI didn't really get that comment in the OP. There's not an API that gives you your entire stored credit card information? Right?
- tisryno 5y agoNo, there's no direct API for that. What the malware does is inject javascript into your discord, so if you add any payment details to your account it will harvest the data and send it via the Webhook to the owner. The injected code also will scan your friends for "rare" badges, like the Bot Developer, Early Supporter and Certified Moderator. They use this information to then target the malware to those people in the hopes they can sell the rare badge accounts.
- tisryno 5y agoInteresting article, but this type of malware has been spreading for months now. PirateStealer is definitely the most popular but it's been shutdown a few times by a discord group who are targeting this type of malware. One of the tools they've built is https://sketchy.tel/ https://sketchy.tel/ which can decompile piratestealer/extrack/bby.rip and more and shuts down the Webhook automatically. There's a lot of other things we do in this community but I can't disclose it because we never know who's reading our messages and if they get found out the malware creators will adapt to stop us.
- timwis 5y agoIs it not possible for discord to mitigate this vulnerability?
- tisryno 5y agoI don't know the specifics, but I'd assume not, Discord has made big steps recently in stopping this sort of malicious activity by adding the "Report Spam" feature as well as creating their own phishing link database to help detect spam in private messages. Discord knows it's a big issue and I'd hope they've attempted to mitigate the malware but there's no way to stop the actual injection, so really all they can do is code shuffle frequently to make the injected code redundant, but that'd rely on doing releases frequently and hoping everyone updates just as frequently.
- atdrummond 5y agoI'm glad to hear they're taking things more seriously. They banned my original Discord account when I showed them a critical bug that allowed for remote viewing of another user's activity, both in real time and in logs.
- tisryno 5y agoYeah, Discord is still just a bad with that. If you join a server and find it's hosting illegal material and proceed to report the server, Discord will ban all members of that server, which includes you. It's created an environment in which no one wants to report anything to Discord, especially since if you appeal your ban you won't get unbanned as you were in the server.
- thih9 5y ago> I downloaded it in a Linux VM so if it gets infected in some ways, I can delete the VM Note that, though rare, some malware can escape from a VM: https://en.m.wikipedia.org/wiki/Virtual_machine_escape https://en.m.wikipedia.org/wiki/Virtual_machine_escape
- izanagi1995 5y agoHey, I am the author of the article. Thanks for the buzz here, it's amazing! I just published on Hackernoon for the non-Medium members: https://hackernoon.com/about/thedevopsguy https://hackernoon.com/about/thedevopsguy. Also, you can find me on Twitter: https://twitter.com/a_devops_guy https://twitter.com/a_devops_guy and Discord: https://discord.gg/FKuAky4K8M https://discord.gg/FKuAky4K8M
- malf 5y agoAnd here I thought irc was dead. Awww!
- jer0me 5y agoAs the maintainer of a moderately popular Minecraft mod, I deal with “ratted” versions all the time. They are often obfuscated with popular free tools that can be reversed, and they always seem to use Discord webhooks that can be instantly deleted. I’ve seen hundreds, and they never seem to evolve in their methods, thought there have been some really nasty ones.